MAL-2026-14134

    Dashboard / Malicious Package / MAL-2026-14134

    MAL-2026-14134

    Published: 18 Aug 2026Last Modified: 18 Aug 2026

    Summary: Malicious code in @mohamed_nowisar/depconf-canary-test (npm)

    Details: Source: amazon-inspector (078a8dc3351eb44ee9ff0d5992b9082b726d7fbce0152ae2d44595a9e279ef82) On `npm install`, the package's preinstall hook runs `node beacon.js`, which collects host identity (os.hostname(), os.userInfo().username, process.cwd(), platform, arch, Node version) and CI-detection environment variables (GITLAB_CI, GITHUB_ACTIONS, YANDEX_CI, and others) and POSTs them as JSON to the hardcoded endpoint https://webhook.site/3687e44a-4e97-43c4-84c9-e6c93d4b2fbc. The package name and self-description frame this as a dependency-confusion canary, but the beacon fires automatically on install without opt-in and sends installer-side data to an author-controlled webhook.site collector.

    Affected packages

    Package

    Name: @mohamed_nowisar/depconf-canary-test

    Purl: pkg:npm/%40mohamed_nowisar/depconf-canary-test

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.1
    MAL-2026-14134 | CVE-DB